Splunk LDAP to AD Auth Fails if AD server is IPv6-based

New Member

Problem: Enabling Splunk LDAP authentication to an Active Directory server fails, if IPv6 is enabled on the server and tries to connect to the Active Directory server over an IPv6 address.

During this time, logging in using AD credentials either take 30 mins (very long time) or fails completely.

The workaround is to make sure you specify the IPv4 address of the Active Directory explicitly within Splunk. If you specify the DNS entry of the Active Directory, make sure when Splunk does an nslookup on the IP, that it doesn't use an IPv6 address.


0 Karma

Splunk Employee
Splunk Employee

IPv6 support is available only from Splunk 4.3 release onwards, you should not see this problem in 4.3, if you do, to debug try disabling the referrals it could be the referrals issue

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!